Windows Process Execution with 'University of California, Berkeley' Description

Alerts on Windows process creation events whose Description contains "University of California, Berkeley."

FreeReviewedSigma · Informational · v5
Product
windows
Category
process_creation
Author
Matt Anderson (Huntress) (SigmaHQ), DRL 1.1
Published
2024-07-23
Updated
2026-07-31

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags newly created Windows processes whose recorded Description contains the text "University of California, Berkeley." Adversaries may reuse legitimate software branding or bundled components to blend in with expected scientific or computing tools. The detection relies on process creation telemetry and the Description field in the event to identify the specific metadata string.

Related detections3 linkedT1553 — drag to rearrange
Windows: Detect execution of renamed BOINC.exe binary
macOS Script Editor Spawns Suspicious Command-Line Interpreters
Windows: Suspicious explorer.exe Child Process Spawned by RazerInstaller.exe
Windows Process Execution with 'University of California, Berkeley' Description
Pivot detection · T1553 · 3 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.